First published: Wed Jan 03 2018(Updated: )
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is set. This is fixed in 2.4.2-RELEASE. OPNsense, a 2015 fork of pfSense, was not vulnerable since version 16.1.16 released on June 06, 2016. The unprotected web form was removed from the code during an internal security audit under "possibly insecure" suspicions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgate pfSense | <=2.4.1 | |
Opnsense Project Opnsense | <16.1.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000479 is a vulnerability in pfSense versions 2.4.1 and lower that allows clickjacking attacks resulting in privileged execution of arbitrary code.
CVE-2017-1000479 has a severity rating of 8.8 (high).
Versions 2.4.1 and lower of pfSense are affected by CVE-2017-1000479.
To fix CVE-2017-1000479, update to pfSense version 2.4.2-RELEASE or newer.
No, OPNsense is not affected by CVE-2017-1000479.